PeerTube/server/middlewares/validators/shared/videos.ts

227 lines
6.2 KiB
TypeScript
Raw Normal View History

import { Request, Response } from 'express'
2022-06-22 09:44:08 +02:00
import { isUUIDValid } from '@server/helpers/custom-validators/misc'
import { loadVideo, VideoLoadType } from '@server/lib/model-loaders'
2022-02-11 10:51:33 +01:00
import { isAbleToUploadVideo } from '@server/lib/user'
2022-06-22 14:03:50 +02:00
import { authenticatePromise } from '@server/middlewares/auth'
import { VideoModel } from '@server/models/video/video'
import { VideoChannelModel } from '@server/models/video/video-channel'
import { VideoFileModel } from '@server/models/video/video-file'
import {
MUser,
MUserAccountId,
2022-02-11 10:51:33 +01:00
MUserId,
MVideo,
MVideoAccountLight,
MVideoFormattableDetails,
MVideoFullLight,
2021-06-11 14:09:33 +02:00
MVideoId,
MVideoImmutable,
MVideoThumbnail,
MVideoWithRights
2020-06-18 10:45:25 +02:00
} from '@server/types/models'
2022-06-22 09:44:08 +02:00
import { HttpStatusCode, ServerErrorCode, UserRight, VideoPrivacy } from '@shared/models'
2019-07-23 10:40:39 +02:00
async function doesVideoExist (id: number | string, res: Response, fetchType: VideoLoadType = 'all') {
2019-07-23 10:40:39 +02:00
const userId = res.locals.oauth ? res.locals.oauth.token.User.id : undefined
const video = await loadVideo(id, fetchType, userId)
2019-07-23 10:40:39 +02:00
2022-06-22 09:44:08 +02:00
if (!video) {
res.fail({
status: HttpStatusCode.NOT_FOUND_404,
message: 'Video not found'
})
2022-06-22 09:44:08 +02:00
2019-07-23 10:40:39 +02:00
return false
}
2019-08-15 11:53:26 +02:00
switch (fetchType) {
case 'for-api':
res.locals.videoAPI = video as MVideoFormattableDetails
break
2019-08-15 11:53:26 +02:00
case 'all':
res.locals.videoAll = video as MVideoFullLight
break
case 'only-immutable-attributes':
res.locals.onlyImmutableVideo = video as MVideoImmutable
break
2019-08-15 11:53:26 +02:00
case 'id':
2021-06-11 14:09:33 +02:00
res.locals.videoId = video as MVideoId
2019-08-15 11:53:26 +02:00
break
case 'only-video':
2019-08-20 13:52:49 +02:00
res.locals.onlyVideo = video as MVideoThumbnail
2019-08-15 11:53:26 +02:00
break
}
2019-07-23 10:40:39 +02:00
return true
}
2022-06-22 09:44:08 +02:00
// ---------------------------------------------------------------------------
async function doesVideoFileOfVideoExist (id: number, videoIdOrUUID: number | string, res: Response) {
if (!await VideoFileModel.doesVideoExistForVideoFile(id, videoIdOrUUID)) {
res.fail({
status: HttpStatusCode.NOT_FOUND_404,
message: 'VideoFile matching Video not found'
})
return false
}
return true
}
2022-06-22 09:44:08 +02:00
// ---------------------------------------------------------------------------
2019-08-15 11:53:26 +02:00
async function doesVideoChannelOfAccountExist (channelId: number, user: MUserAccountId, res: Response) {
2021-04-06 17:01:35 +02:00
const videoChannel = await VideoChannelModel.loadAndPopulateAccount(channelId)
2019-07-23 10:40:39 +02:00
2021-04-06 17:01:35 +02:00
if (videoChannel === null) {
res.fail({ message: 'Unknown video "video channel" for this instance.' })
2021-04-06 17:01:35 +02:00
return false
}
// Don't check account id if the user can update any video
if (user.hasRight(UserRight.UPDATE_ANY_VIDEO) === true) {
2019-07-23 10:40:39 +02:00
res.locals.videoChannel = videoChannel
return true
}
2021-04-06 17:01:35 +02:00
if (videoChannel.Account.id !== user.Account.id) {
res.fail({
message: 'Unknown video "video channel" for this account.'
})
2019-07-23 10:40:39 +02:00
return false
}
res.locals.videoChannel = videoChannel
return true
}
2022-06-22 09:44:08 +02:00
// ---------------------------------------------------------------------------
2022-06-22 09:44:08 +02:00
async function checkCanSeeVideo (options: {
req: Request
res: Response
paramId: string
video: MVideo
authenticateInQuery?: boolean // default false
}) {
const { req, res, video, paramId, authenticateInQuery = false } = options
if (video.requiresAuth()) {
return checkCanSeeAuthVideo(req, res, video, authenticateInQuery)
}
2022-06-22 09:44:08 +02:00
if (video.privacy === VideoPrivacy.UNLISTED) {
if (isUUIDValid(paramId)) return true
2022-06-22 09:44:08 +02:00
return checkCanSeeAuthVideo(req, res, video, authenticateInQuery)
}
2022-06-22 09:44:08 +02:00
if (video.privacy === VideoPrivacy.PUBLIC) return true
throw new Error('Fatal error when checking video right ' + video.url)
}
2022-06-22 09:44:08 +02:00
async function checkCanSeeAuthVideo (req: Request, res: Response, video: MVideoId | MVideoWithRights, authenticateInQuery = false) {
const fail = () => {
2022-02-11 10:51:33 +01:00
res.fail({
status: HttpStatusCode.FORBIDDEN_403,
2022-06-22 09:44:08 +02:00
message: 'Cannot fetch information of private/internal/blocked video'
2022-02-11 10:51:33 +01:00
})
return false
}
2022-06-22 14:03:50 +02:00
await authenticatePromise(req, res, authenticateInQuery)
2022-06-22 09:44:08 +02:00
const user = res.locals.oauth?.token.User
if (!user) return fail()
const videoWithRights = (video as MVideoWithRights).VideoChannel?.Account?.userId
? video as MVideoWithRights
2022-06-28 14:57:51 +02:00
: await VideoModel.loadFull(video.id)
2022-06-22 09:44:08 +02:00
const privacy = videoWithRights.privacy
if (privacy === VideoPrivacy.INTERNAL) {
// We know we have a user
return true
}
const isOwnedByUser = videoWithRights.VideoChannel.Account.userId === user.id
2022-06-22 14:03:50 +02:00
if (videoWithRights.isBlacklisted()) {
if (isOwnedByUser || user.hasRight(UserRight.MANAGE_VIDEO_BLACKLIST)) return true
2022-06-22 09:44:08 +02:00
return fail()
}
2022-06-22 14:03:50 +02:00
if (privacy === VideoPrivacy.PRIVATE || privacy === VideoPrivacy.UNLISTED) {
if (isOwnedByUser || user.hasRight(UserRight.SEE_ALL_VIDEOS)) return true
2022-06-22 09:44:08 +02:00
return fail()
}
// Should not happen
return fail()
}
2022-06-22 09:44:08 +02:00
// ---------------------------------------------------------------------------
2020-11-02 15:43:44 +01:00
function checkUserCanManageVideo (user: MUser, video: MVideoAccountLight, right: UserRight, res: Response, onlyOwned = true) {
2019-07-23 10:40:39 +02:00
// Retrieve the user who did the request
2020-11-02 15:43:44 +01:00
if (onlyOwned && video.isOwned() === false) {
res.fail({
status: HttpStatusCode.FORBIDDEN_403,
message: 'Cannot manage a video of another server.'
})
2019-07-23 10:40:39 +02:00
return false
}
// Check if the user can delete the video
// The user can delete it if he has the right
// Or if s/he is the video's account
const account = video.VideoChannel.Account
if (user.hasRight(right) === false && account.userId !== user.id) {
res.fail({
status: HttpStatusCode.FORBIDDEN_403,
message: 'Cannot manage a video of another user.'
})
2019-07-23 10:40:39 +02:00
return false
}
return true
}
2022-06-22 09:44:08 +02:00
// ---------------------------------------------------------------------------
2022-02-11 10:51:33 +01:00
async function checkUserQuota (user: MUserId, videoFileSize: number, res: Response) {
if (await isAbleToUploadVideo(user.id, videoFileSize) === false) {
res.fail({
status: HttpStatusCode.PAYLOAD_TOO_LARGE_413,
message: 'The user video quota is exceeded with this video.',
type: ServerErrorCode.QUOTA_REACHED
})
return false
}
return true
}
2019-07-23 10:40:39 +02:00
// ---------------------------------------------------------------------------
export {
doesVideoChannelOfAccountExist,
doesVideoExist,
doesVideoFileOfVideoExist,
2022-02-11 10:51:33 +01:00
checkUserCanManageVideo,
2022-06-22 09:44:08 +02:00
checkCanSeeVideo,
2022-02-11 10:51:33 +01:00
checkUserQuota
2019-07-23 10:40:39 +02:00
}